2016-08-18

Added · Updated

Application form and notes for payment service providers

De Nederlandsche Bank requires applicants for payment service provider licences to comply with the European Digital Operational Resilience Act (DORA) for ICT outsourcing, information systems security, data collection, incident follow-up, and business continuity management as of 17 January 2025. Applicants must submit a business plan, budget estimates for three years, and proof of minimum own funds to demonstrate financial soundness. The application process involves a two-phase assessment by DNB, with potential information sharing with the AFM and the Dutch Data Protection Authority.

De Nederlandsche Bank logo

Netherlands

De Nederlandsche Bank

Click to view thumbnail

Licence application for payment service providers

DORA update 3.8 Outsourcing As of 17 January 2025, ICT outsourcing is subject to the European Digital Operational Resilience Act (DORA). Where requirements in this document relate to ICT outsourcing, these requirements must be read as the requirements from DORA. Level 1 Legislation: DORA - Chapter V, Articles 28-30 Level 2 Technical standards: 1) RTS to specify the policy on ICT services performed by ICT third-party providers, 2) RTS on subcontracting of critical or important functions, 3) ITS to establish the templates for the register of information. See our OBT DORA page for more details. 3.10 Information systems, infrastructure and security As of 17 January 2025, ICT outsourcing is subject to the European Digital Operational Resilience Act (DORA). Where requirements in this document relate to ICT outsourcing, these requirements must be read as the requirements from DORA. Level 1 Legislation: DORA - Chapter V, Articles 28-30 Level 2 Technical standards: 1) RTS to specify the policy on ICT services performed by ICT third-party providers, 2) RTS on subcontracting of critical or important functions, 3) ITS to establish the templates for the register of information. See our OBT DORA page for more details. 3.12 Secure communication As of 17 January 2025, ICT management and security of ICT Information Systems and ICT infrastructure are subject to the European Digital Operational Resilience Act (DORA). Where requirements in this document relate to ICT Information Systems, ICT Infrastructure and ICT Security, these requirements should be replaced with the requirements from DORA. Level 1 Legislation: DORA - Chapter II, Articles 5-16 Level 2 Technical standards: RTS on ICT risk management framework and RTS on simplified ICT risk management framework. See our OBT DORA page for more details. 3.13 Data collection As of 17 January 2025, data collection is subject to the European Digital Operational Resilience Act (DORA). Where requirements in this document refer to data collection, these requirements should be replaced by the requirements from DORA. Level 1 Legislation: DORA - Chapter II, Article 15 Level 2 Technical standards: RTS on ICT risk management framework and RTS on simplified ICT risk management framework. See our OBT DORA page for more details.

3.14 Follow-up of Incidents As of 17 January 2025, the classification, follow-up and reporting of major ICT incidents are subject to the European Digital Operational Resilience Act (DORA). Where requirements in this document relate to ICT incidents, these requirements should be replaced by the requirements from DORA. Level 1 Legislation: DORA - Chapter III, Articles 17-20 Level 2 Technical standards: 1) RTS on criteria for the classification of ICT-related incidents, 2) RTS and ITS on content, timelines and templates on incident reporting. See our OBT DORA page for more details. 3.15 Business continuity management As of 17 January 2025, business (ICT) continuity management is subject to the European Digital Operational Resilience Act (DORA). Where requirements in this document relate to business (ICT) continuity management, these requirements should be replaced by the requirements from DORA. Level 1 Legislation: DORA - Chapter II, Article 15 Level 2 Technical standards: RTS on ICT risk management framework and RTS on simplified ICT risk management framework. See our OBT DORA page for more details. Explanatory notes to the licence application form for payment service providers - PSD2 De Nederlandsche Bank Under the Financial Supervision Act (Wet financieel toezicht – Wft), De Nederlandsche Bank (DNB) is charged with the prudential supervision of payment institutions and with deciding whether to allow payment institutions access to the financial market. Within the context of its supervisory tasks, DNB has the statutory power to share information with the Dutch Authority for the Financial Markets (AFM) and the Dutch Data Protection Authority (DPA). This includes sharing information about licence applications. Dutch Authority for the Financial Markets Under the Wft, the AFM is responsible for conduct supervision of payment institutions, which can be relevant to certain parts of the licence application process. Dutch Data Protection Authority Pursuant to the General Data Protection Regulation (GDPR), the Dutch Data Protection Authority (DPA) is responsible for supervision of personal data processing, which can be relevant to certain parts of the licence application process.

4 DNB Licence application for payment service providers Contents 1 General information 6 1.1 Company data 6 1.2 External consultant contact details 6 1.3 If you are already operating as a payment service provider or exempt payment service provider 6 1.4 If you are subject to financial supervision by a foreign supervisory authority 6 1.5 Conditions for licence application 6 1.6 Licence application procedure 9 2 Business case 10 2.1 Business plan 10 2.2 Funds flow chart 11 2.3 Recovery and exit plan 11 3 Operational management set-up for sound business operations 13 3.1 Risk analysis for the purpose of managing operational processes and operational risks 13 3.2 Risk management framework 14 3.3 A clear, balanced and adequate organisational structure 15 3.4 Compliance function 17 3.5 Internal control function 18 3.6 Procedures manual 18 3.7 External audit 19 3.8 Outsourcing 19 3.9 International services 21 3.10 Information systems, infrastructure and security 22 3.11 Authentication 23 3.12 Secure communication 24 3.13 Data collection 24 3.14 Follow-up of incidents 25 3.15 Business continuity management 26 3.16 Sound remuneration policy 27 3.17 Oath or affirmation 28 3.18 Education and training 28

5 DNB Licence application for payment service providers 4 Operational management set-up for ethical business operations 29 4.1 Systematic integrity risk analysis (SIRA) 29 4.2 Preventing conflicts of interests 30 4.3 Propriety in integrity-sensitive positions 31 4.4 Customer due diligence 31 4.5 Sanctions Act 1977 (Sanctiewet 1977 – Sw) 32 4.6 Transaction monitoring and reporting of unusual transactions 33 5 Fit and proper assessment of policymakers and co-policymakers 34 5.1 Fitness of policymakers 34 5.2 Propriety of policymakers and co-policymakers 34 6 Two day-to-day policymakers working from the Netherlands 36 7 Transparent control structure 37 8 Qualifying holdings 38 9 Securing the funds of payment service users 39 10Minimum own funds and solvency 41 10.1 Minimum own funds 41 10.2 Required actual own funds as part of solvency 41 11 Liability insurance 43 Annex 45

6 DNB Licence application for payment service providers 1 General information 1.1 Company data We ask you to provide us with a number of details about your company. We also ask that you submit a number of documents, including a certified copy of the notarial deed containing the company’s articles of association. Please make sure that the object described in the articles of association actually reflects the services that your company will provide. The description of the company’s object may not include activities that require another licence, unless you already hold a licence for these activities. If you do not yet have a copy of the notarial deed containing the company’s articles of association, a final draft version will suffice for the purpose of processing your application. Please note that we will not decide on your application until we have received a certified copy of your company’s articles of association. 1.2 External consultant contact details We recommend that you engage the services of a consultant to assist you in the application process. Practice has shown that applications are often more complete and of a substantially higher quality if the applicant has sought expert advice, for example from a legal expert who specialises in the Dutch Financial Supervision Act (Wet op het financieel toezicht – Wft). We can assess complete and well-substantiated applications faster and more thoroughly. If you decide to engage the services of an external consultant, please also provide us with their particulars. 1.3 If you are already operating as a payment service provider or exempt payment service provider You may already be operating as a payment service provider. If so, we assume that you have verified that you do not provide any services that are subject to a licence requirement. If you indicate that you are already operating under the Exemption Regulation under the Wft (Vrijstellingsregeling Wft), we would ask you to state the date of your registration as an exempt payment service provider. If you are active as a payment service provider but not registered as an exempt payment service provider, please specify. If you already hold a licence as a payment institution, please state to which payment services this applies. 1.4 If you are subject to financial supervision by a foreign supervisory authority Please state whether your company (or another group company) is subject to financial supervision by a foreign supervisory authority. If this is the case, please specify the type of financial activities involved, the country, and the name of the supervisory authority in question. If you used to be subject to financial supervision by a foreign supervisory authority, please state this and specify why this is no longer the case. 1.5 Conditions for licence application A payment service provider (PSP) is a company whose business it is to provide payment services. This definition is based on Section 1:1 of the Wft. These services are provided to persons making payments (consumers) or parties using the payment services (retailers), or both. So a payment service provider acts as an intermediary between the two. To determine whether a company qualifies as a payment service provider, the following questions must be answered:

  1. Do the proposed activities qualify as a payment service? Please note that there are specific services that the Wft explicitly does not qualify

7 DNB Licence application for payment service providers as payment services. These services are excepted from the licence requirement. 2. Will it be your company’s “business” to provide payment services? 3. Is your company subject to the Exemption Regulation under the Wft? Check whether any of the statutory exceptions apply. Several specific services explicitly do not qualify as payment services under the Wft. These exceptions are listed in Section 1:5a(2). Examples include commercial agents and limited networks. Please consult the FAQs on Open Book on Supervision for more details on these exceptions. Does your company provide payment services within the meaning of Section 1:1 of the Wft? First you must verify whether your company is a payment service provider within the meaning of Section 1:1 of the Wft. There are eight types of payment services. These services may be provided as a single service or in any combination. They are listed and defined in the Annex to the revised Payment Services Directive (EU) 2015/2366 (PSD2). The Wft refers to that Annex.

  1. Services enabling cash to be placed on a payment account held with the payment service provider as well as all the operations required for operating a payment account. These services enable users to pay cash (coins and banknotes) into a payment account held with the service provider.
  2. Services enabling cash withdrawals from a payment account as well as all the operations required for operating a payment account. These services enable users to withdraw funds in cash from a payment account held with the service provider.
  3. Execution of payment transactions, including funds transfers on a payment account held with the user’s payment service provider or with another payment service provider. „ Execution of direct debits, including one-off direct debits „ Execution of payment transactions by means of a debit card or a similar payment instrument „ Execution of transfers of funds, including standing orders. These services entail executing payment transactions on the payment accounts of payment services users as meant in the description of services 1 and 2, or on the user’s payment account held with another payment service provider. This also includes services enabling users to withdraw or deposit cash using a cash dispenser or cash deposit machine, with the equivalent amount being debited from or credited to a payment account.
  4. Execution of payment transactions where the funds are covered by a credit line for a payment service user: „ Execution of direct debits, including one-off direct debits „ Execution of payment transactions by means of a debit card or a similar payment instrument „ Execution of transfers of funds, including standing orders. A credit line may include a situation in which the payment service provider advances the amount due.
  5. Services involving the issuance of payment instruments and/or the acceptance of payment transactions A payment instrument is a means or method to initiate a payment order. A payment instrument can be a physical object such as a card (e.g. a credit card), but also a set of

8 DNB Licence application for payment service providers procedures. Acquiring (or accepting) payment transactions means that a company guarantees the settlement of transactions by means of an agreement concluded with the payee, e.g. an online retailer. The acquiring entity, or acquirer, handles payments to the payee based on the payment orders received. Companies providing services to retailers, including online retailers, for the acceptance of payment instruments provide type 5 services. 6. Money transfers. Money transfers are involved if a payment institution receives funds from a payer for the sole purpose of transferring the corresponding amount either directly to a payee or to another payment service provider who pays out the funds to the ultimate beneficiary. No payment account is created in the name of the payer. In practice, money transfers are used mainly to transfer funds to beneficiaries abroad, in particular in countries with less sophisticated banking systems and a less widespread use of bank accounts. They are also sometimes used to effectuate unexpected urgent payments. 7. Payment initiation services. At a payment service user’s request, a payment service provider initiates a payment order from an online payment account held with another payment service provider. For example initiating an online purchase at a webshop on behalf of a consumer. 8. Account information services. An account information services provider provides consolidated information on one or more payment accounts held by the payment service user by one or more payment service providers. We recommend that you consult with a legal expert on this. In the application form, we ask you to explain the legal qualification under PSD2 of your company’s activities. Please state in the application form whether you intend to provide intermediation services for products and services. For the provision of intermediation services in financial products, you may need a licence issued by the AFM. For more information go to www.afm.nl. The application form contains the following three verification questions to ensure you apply for the correct licence for the payment services and to check whether you would require an additional licence:

  1. Does your company intend to offer intermediation services for products and services at any point?
  2. Does your company intend to offer lending services at any point?
  3. Will your company manage customer accounts at any point? Will your company provide payment services on a commercial basis? Payment service providers are subject to the licence requirement if they provide payment services on a commercial basis. Providing services to several customers is an indication that these services are provided on a commercial basis. You are in any case subject to the licence requirement if you are actively promoting payment services, e.g. by advertising. If a company provides payment services on a one-off or very incidental basis, it does not qualify as a payment service provider. If you are in doubt about the legal qualification of your proposed activities, we recommend that you consult a legal expert.

9 DNB Licence application for payment service providers IBAN issue Do you intend to offer payment accounts with a Dutch IBAN (as referred to in the SEPA Regulation)? Then you are legally obliged to register with the Banking Information Reference Portal. You must ensure this registration is completed before you start providing services. For more information, see our Open Book on Supervision: https://www.dnb.nl/en/sector￾information/open-book-supervision/open-book￾supervision-themes/supervision-of-financial￾crime-prevention-integrity-supervision/ banking-information-reference-portal/. 1.6 Licence application procedure After submission of your application „ After submitting your application digitally via MyDNB, you will receive a confirmation of receipt. Phase 1: Checking the completeness of your application „ We will check whether all required information and documents are submitted with your application. „ We will start our assessment of your application only when it is complete. „ We only process applications that are submitted in full. If your application is incomplete, you will have the opportunity to submit the missing documents within a specified deadline. In Phase 1, we generally request for missing documents only once. If you do not provide all requested documents (on time) and the application is still incomplete, the application may be dismissed and Phase 2 will not start. „ An incomplete or inaccurate application not only leads to delays but may also result in the application not being considered or rejected. Moreover, even in those situations, you will still have to pay the licence application fee. „ We therefore strongly recommend that you do not submit your application until it is complete. Check that all questions from the application form (taking into account these Explanatory notes) have been answered substantively and fully, all attachments are attached and the information provided is accurate and up to date. Once the application is complete, the statutory three-month consideration period begins. We will notify you of this in writing. Phase 2: Substantive assessment of your application „ In this phase, we assess whether you meet all licensing requirements. „ If we need additional information, you will be asked for an explanation or supplementary documents. The consideration period will then be suspended. „ The assessment of policymakers and co-policymakers also takes place in this phase. „ Within the consideration period we will let you know whether you will be granted a licence, or if we intend to reject your application. For more information, see the fact sheet on Open Book on Supervision: Application process (10 steps).

10 DNB Licence application for payment service providers 2 Business case 2.1 Business plan When applying for a licence, you must submit a business plan on behalf of the company, including a programme of operations. You must also submit a budget estimate for the first three financial years, which demonstrates that you have appropriate systems, resources and procedures in place that allow you to operate in a financially sound and healthy manner. You can submit the business plan and budget forecast as a single document, but please bear in mind that this information must be consistent with the information to be submitted in the templates described in Section 10 regarding the Minimum own funds and solvency. We expect you to submit at least the following elements: „ A schematic overview of the company’s activities elaborated per payment service and a detailed description of how the payment services will be provided. If your company intends to offer payment accounts (payment services 1 and 2), you must specify and substantiate whether the fallback mechanism will be used or an exception is requested. Please also provide a list of your company’s other activities (including activities not subject to the licence requirement). „ A description of operational and closely related ancillary services, as referred to in Article 18(1) of PSD2. Ancillary services are services related to the payment services. You must also describe any ambitions to provide such services for the coming three years. „ The company strategy, including the following aspects: 1 This is an analysis of your company’s strengths and weaknesses, proving a clear overview of the potential success of your proposed services in diagram form (e.g. in a matrix). S = Strengths, W = Weaknesses, O = Opportunities, T = Threats. Based on a SWOT analysis, you can define objectives and subsequently devise a strategy for achieving these objectives.

  • the intended market share for each payment solution
  • the intended origin of payment service users
  • a well-considered description of the company’s growth ambitions
  • a SWOT analysis.1
  • contracting out of processes
  • the company’s professional partners (e.g. acquirers, customer referrals). „ For existing companies: audited financial statements over the past three years, or an opening balance sheet signed by the management board if the company has not yet issued financial statements. „ Based on the company strategy, a projection of your company’s financial position and estimated results for the current financial year and the next three years, including a full profit and loss account and a balance sheet, detailing the following aspects:
  • The expected own funds of the company, in connection with the information to be submitted in the templates described in Section 10 regarding minimum own funds and solvency.
  • The assumptions and calculations underlying your financial projections, such as investment costs, outsourcing costs, management costs, contributions and your envisaged market share.
  • The company’s policy to ensure business continuity under normal, moderately adverse and highly adverse circumstances. See also Recovery plan.
  • A detailed specification of estimated inward and outward cash flows – i.e. your liquidity position – for the next three years, presented in a chart.

11 DNB Licence application for payment service providers „ A marketing plan including an analysis of your company’s competitive position and a description of the users for each of the payment services concerned and the proposed marketing activities and distribution channels. „ An estimate of the number and a description of the locations from which the company will be operating its payment services and related activities. 2.2 Funds flow chart This section does not apply to you if you only provide payment service types 7, 8 or both. When assessing your application, we must have a clear picture of the cash flows related to your proposed activities. Please provide an overview of the anticipated cash flows for each type of payment service in the form of a flow chart, indicating for each payment instrument the number of transactions, the processing times and the parties involved. 2.3 Recovery and exit plan You must draw up a recovery plan, setting out how your company will recover from adverse financial circumstances. Such a plan must in any event describe the measures in place for detection of and timely recovery from any deterioration of the company’s financial situation. The aim of this plan is to restore to a stable financial situation as soon as possible. In addition to a recovery plan, you must draw up an exit plan in timely preparation for the potential termination or transfer of the company’s business activities. If your company actually needs to be resolved, the plan ensures that liquid funds can be paid out or continue to be paid out in an orderly fashion and with the least adverse effects possible for payment service users and other stakeholders, and that relevant data will be removed. Although the recovery plan and exit plan serve different purposes, you can combine them in a single plan. This means you will only have to upload a single document. In the remainder of this text, we will therefore refer to the “recovery and exit plan”. Obviously, the recovery and exit plan must be consistent with your business plan. The recovery and exit plan must cover all of the company’s business activities, products and processes. The recovery and exit plan must have a clear responsible owner within the company, requires the prior approval of the management board and – if applicable – the supervisory board, and must be reviewed periodically. This must also be stated in the plan. The plan should be based on the principle of proportionality, and it is up to you as a company to determine the level of detail of the plan. The recovery and exit plan must include several stress scenarios, with associated costs. The scenarios must include the underlying assumptions, such as the number of transactions and their value, the number of customers, pricing and the average amount per transaction. This demonstrates that your company’s business case is robust enough to be able to meet your obligations even in the event of disappointing results and/or circumstances. The recovery and exit plan must also include an elaboration of the process for paying out third-party funds to owners. You must elaborate on how payment blocks, i.e. untraceable owners of funds in the wallets, will be handled. We expect you to elaborate on the process for paying out third￾party funds to customers, including the procedure for handling payment blocks and untraceable owners of funds in the wallets.

12 DNB Licence application for payment service providers In the context of our thematic examination into recovery and exit plans of payment institutions, we provided a guidance document to help you prepare these plans. You can find it on Open Book on Supervision (Recovery and exit plan | De Nederlandsche Bank). Your company’s recovery and exit plan must include all the elements described in this guidance document. In addition, the recovery and exit plan must specifically address the controlled management of payment service users’ data in the event of the company’s resolution. We have also compiled a good practices document with advanced insights gained on the basis of the recovery and exit plans submitted by payment institutions. It may help you in preparing your company’s own recovery and exit plan. The document is available on Open Book on Supervision (https://www.dnb.nl/media/ aykgswat/good-practice-herstel-en-exitplannen￾betaalinstellingen.pdf).

13 DNB Licence application for payment service providers 3 Operational management set-up for sound business operations Your company must be organised in such a way as to ensure sound and ethical business operations. This means that you must analyse the operational risks to which your company is exposed and take measures to mitigate these risks. If you use a customer accounts foundation to protect the funds of payment service users, your must also include this foundation in the risk analysis. Any outsourced activities must also be included in the risk analysis. Our assessment of sound business operations includes the following elements: „ Risk analysis for the purpose of managing operational processes and operational risks. „ Risk management framework „ A clear, balanced and adequate organisational structure „ Compliance function „ Internal audit function „ Procedures manual „ External audit „ International services „ Information systems, infrastructure and security „ Authentication „ Secure communication „ Data collection „ Outsourcing „ Incident management „ Business continuity management „ Sound remuneration policy „ Oath or affirmation „ Training We will explain this in more detail below. 3.1 Risk analysis for the purpose of managing operational processes and operational risks You must submit a recent, comprehensive analysis of the risks that are inherent to your company and the services it provides, so that we can determine whether your company’s operational management organisation is appropriate to the risks it is exposed to. The analysis must also include an assessment of the measures and control mechanisms in place to mitigate these risks. You should base your risk analysis on the risk management framework designed by your company. Sound operational management as a payment services provider starts with identifying the relevant risks. Such a risk analysis is a precondition for the adequate organisation of sound business operations. The analysis must be verifiable, i.e. recorded in a separate document, and the remainder of your risk management framework must be based in part on the outcome of the risk analysis. You should apply a clear quantification method. The SIRA is based on gross (inherent) and net (residual) risks and analyses the likelihood and impact of these risks. The size of net risks must be clear and the measures and procedures must have a plausible impact. In analysing the net risks, you should also consider your company’s risk appetite. See also the section on the risk management framework.

14 DNB Licence application for payment service providers As a minimum, the risk analysis contains an analysis of the risks that are relevant to your company, You should consider the following risk categories: credit risk, market risk, interest rate risk, concentration risk, liquidity risk2 , operational risk (including IT and outsourcing risk), insurance risk and integrity risk (a systematic integrity risk analysis or SIRA must be submitted separately under the section regarding the organisation of operational management to ensure ethical business operations. You should then address the risks underlying each of the risk categories. The analysis must address the underlying inherent risks for each of these categories and, these risks if they are high, show the measures in place to mitigate them. In particular, it must address the risks related to the payment services and include a description of security control and mitigation measures taken to adequately protect payment service users against the risks identified, including fraud and illegal use of sensitive and personal data. To this end, you must also prepare a security policy, see Section 3.10. Your procedures and measures must be verifiably connected with the specific risks identified in the risk analysis. The controls must be demonstrably appropriate to the nature, size, complexity and risk profile of the activities of your company and must meet the minimum requirements set out above. 2 The liquidity risk management procedures and measures must focus on management of the company’s current and future net financial position and requirements. 3.2 Risk management framework Please describe your company’s risk management framework. This policy document must address your company’s policy aimed at managing relevant risks, including a description of the company’s risk appetite. It must also address the design and organisation of the risk management function and describe how the policy is translated into procedures and measures to manage relevant risks, as well as how it is integrated into the company’s operational processes (see also the section on Procedures manual). You should also demonstrate that this risk management framework enables your company to guarantee sound business operations. We also expect the other components described in this section to be in line with your company’s risk management framework. Your company must have a policy in place aimed at managing relevant risks and in line with the company’s risk appetite. It should include a description of your company’s risk appetite for each of the relevant risk areas, such as credit risk, market risk, interest rate risks, foreign exchange risk, concentration risk, liquidity risk, operational risk (including IT and outsourcing risk), and insurance risk. Your risk management policy must be translated into procedures and measures, which must be appropriate to the nature, size, risk profile, and the complexity of the company’s activities, and address at least the following four areas: „ Authorisation procedures „ Limit allocation „ Limit monitoring „ Emergency procedures and measures

15 DNB Licence application for payment service providers The procedures and measures must be clearly documented, for example in a procedures manual (see Section 3.6). They must be communicated to all payment institution units exposed to the risks, preferably in writing. Your company must have an independent risk management/risk control function that is responsible for systematic risk management within the organisation, focusing on identifying, measuring and evaluating risks that the company is or may be exposed to. Risk management covers the company’s operations as a whole as well as those of its individual business units. The risk management/ risk control function must be given the required authority and access to all information necessary for the performance of its tasks. The description of the risk management/risk control framework must include an explanation of the structure of the risk management/risk control function. We also expect you to provide a description of the periodic and permanent controls that your company has in place, including their frequency, staffing (in FTEs) and resources (in monetary terms). Your company must establish an effective operational IT and security risk management framework, which should be approved and reviewed, at least once a year, by the management body and, where relevant, by senior management. This framework should focus on security measures to mitigate operational and security risks and should be fully integrated into your company’s overall risk management processes. See also the section on the management of operational IT and security risks. 3.3 A clear, balanced and adequate organisational structure In setting up its business operations, your company must base its operational management (including the customer accounts foundation, if applicable), on the following six principles. „ Your company has a clear, balanced and adequate organisational structure. „ Your company has a clear, balanced and adequate distribution of duties, authorities and responsibilities (governance). „ The rights and obligations within your company are adequately documented. „ Your company has clear and unambiguous reporting lines. „ Your company has an adequate information and communication system. „ Your company has a clear and adequately documented operational management structure, which is reviewed at regular intervals. A clear, balanced and adequate organisational structure also includes a substantial presence of the management board (which means that day￾to-day policymakers perform their work for the company substantially from the Netherlands) and key function staff members. In the event that one or more directors of your company also hold the position of director of one or more group entities (‘dual hatting’), you are expected to demonstrate how your company is able to operate independently and how the potential risk of conflicts of interest is mitigated. Your company must have a clear, balanced, and adequate distribution of duties and authorities in place at all levels and in all units of the company. Reporting lines must be in tune with the organisational structure.

16 DNB Licence application for payment service providers The division of tasks and reporting lines must be documented and communicated throughout the company to ensure that all sections of the company have full knowledge of their duties, authorities and responsibilities, their role in the organisation and the control process, and how they are held accountable. If any shortcomings or deficiencies are found, you must ensure that the organisational structure and the procedures and measures are changed so that these are remedied. In a company with a director-major shareholder (DMS) structure or an internationally complex group structure and/ or organisational structure, for example due to many internal dependencies, a high degree of outsourcing or an increased risk of conflicting interests, devoting special attention to balanced corporate governance is appropriate. We expect you to include appropriate notes if this applies to your company. Director-major shareholder (DMS) structure Please state in the application form whether your company has a DMS structure or a comparable control structure. Corporate governance is defined as the distribution of duties, responsibilities and authorities aimed at balancing the influence of those directly involved in the company and its operations, particularly its executive and supervisory directors, and capital providers. It is important that the company at all times has expert and balanced operational management with adequate checks and balances and appropriate incentives. A DMS structure involves a natural person who is both a major shareholder (even if indirectly) and a managing director. In the absence of adequate countervailing power (checks and balances), a DMS may exercise an unduly excessive influence on the company’s day-to-day management. DMSs may find themselves in a situation where they let their own interests as a shareholder prevail over the long-term interests of the company or its stakeholders. Apart from potential conflicts of interest, there is also a risk that a DMS identifies with the company to such an extent that he or she is unable to demonstrate and safeguard the objectivity and independence required in that capacity, for example in the event that the company faces critical problems. We judge the admissibility of a control structure involving one or more DMSs on a case-by￾case basis. If such a structure exists in your company, you must provide evidence in your licence application that you have sufficiently mitigated the vulnerabilities attached to a control structure of this kind. This may include establishing a supervisory board or putting adequate arrangements in place to ensure that carefully considered decisions are taken in case of conflicting interests between the company and the DMS. Complex international structure For complex international structures we expect you to provide evidence of an adequate risk analysis and appropriate mitigation measures. This may for example include establishing a supervisory board. If your company is part of a group of companies, you are responsible for ensuring that its organisational structure and business processes are adequately aligned with those of its subsidiaries and other companies joined together with your company in a formal or actual governance structure. In this way, you will prevent the sound business operations of your company from being undermined.

17 DNB Licence application for payment service providers If your company has a Supervisory Board or intends to establish one, it is essential that this Supervisory Board is able to function independently. For a further explanation, see the Q&A on supervisory board independence (https://www.dnb.nl/en/sector-information/ open-book-supervision/open-book-supervision￾sectors/payment-institutions/prudential￾supervision/qa-on-supervisory-board￾independence-payment-institutions/). Organisation chart We require you to provide a recent organisation chart showing all divisions, departments and other structural units. We expect you to include a list of the people in charge of these divisions, departments and other structural units, with special attention to the individuals in charge of internal control functions (e.g. risk management, management business, compliance, audit) and possible departments. If these people are not yet known, you should include a detailed job profile for these functions/positions. The organisation chart must be accompanied by a description of the functions and responsibilities of the divisions, departments and other structural units, including an estimate of the number of staff and FTEs employed by or working for the company in the next three years. You should also indicate in the chart which functions are outsourced and which staff members occupy multiple roles. Segregation of duties The duties, powers and responsibilities of both individual staff members and departments in your company must be segregated to limit the risk of errors, improper use and/or improper access to assets or data and to adequately manage the risk of conflicts of interest. For instance, job descriptions must not include powers enabling staff members to enter into transactions or liabilities or to authorise, process and settle transactions without an accountability mechanism, to have free access to assets, or to manipulate financial or other data. If your company is small, it may be challenging to realise internal segregation of duties. However, simply stating that it is a challenge in a small organisation does not suffice. We expect you to take alternative measures in this case. One option is to outsource activities to third parties to compensate for the lack of internal segregation of duties. We expect you to be sufficiently in control, and to explain in your application how you intend to safeguard this. See also Section 3.8 on outsourcing. 3.4 Compliance function Your company must have an organisational unit in place that performs an independent and effective compliance function. An independent compliance function is important to monitor compliance with legislation and regulations as well as internal rules, regulations and procedures. Supervision of compliance with rules, regulations and procedures for instance includes assessing new legislation and verifying whether new products and procedures comply with rules and regulations. The actual set-up of the compliance function depends on the nature and size of the payment institution. “Independent” at least means that the compliance function is not influenced by commercial or other interests. The duties and responsibilities of the compliance function must be documented in a compliance charter, and the necessary activities must be further detailed in an annual compliance plan. While submission of the compliance charter and the annual compliance plan is not mandatory, it may contribute to a more comprehensive substantiation of your licence application.

18 DNB Licence application for payment service providers Compliance charter (optional) The compliance charter must include the following elements: „ Definition and scope „ Compliance mission „ The compliance officer’s job profile, including key tasks, powers and responsibilities „ The compliance function’s special status in your company „ Safeguards for segregation of duties „ The names of the internal and/or external compliance officer(s)/staff member(s) The compliance charter clearly sets out the various roles and responsibilities. It is available to the entire organisation as well as to external parties such as supervisory authorities, and clearly sets out what can be expected from the compliance function, from the management and from other staff members in terms of sound and ethical operational management. Annual compliance plan (optional) The annual compliance plan is based on a risk analysis. The plan presents a visible account of the capacity to be deployed, and the compliance function compiles the plan in consultation with the management. The compliance function must also ensure that any other stakeholders agree with the contents of the plan. 3.5 Internal control function Your company must have an organisational unit that performs the internal control function. The effectiveness of the company’s organisation and the procedures and measures must be assessed internally and independently. By “independently” we mean independent of the line management and independent of the controls integrated in the different operational processes. Independent internal control is an ongoing process that includes changing internal and external circumstances, new products and services, and support processes. An internal audit must be performed at least annually. You must describe how your company ensures that any shortcomings identified are eliminated. As you can read in the sections on External audit (3.7) and Outsourcing (3.8), the internal control function can also be outsourced. If the internal audit function is outsourced to another company within the group, we expect you to submit the signed outsourcing agreement with an adequate description and substantiation of this outsourcing. We also expect you to address the annual plan of internal control activities. 3.6 Procedures manual The risk management framework, the organisational structure, the compliance function, and the internal audit function are the main components of your operational management to ensure sound business operations. The overall structure of your operational management is also important, however. You should record your company’s general procedures and measures to support sound business operations in a single clear and accessible document: the procedures manual. The procedures manual translates the structure of your company (the policies that your company pursues) into specific procedures and measures for operational management. It also includes the procedures outlined in your company’s risk management framework for performing periodic and ongoing audits, including their frequency and the staff allocated to these duties. This means that if you have not yet detailed the procedures and measures that your company has in place in the

19 DNB Licence application for payment service providers risk management framework, the organisational structure, the compliance function and/or the internal audit function, we expect you to do this in your procedures manual. You must compile a procedures manual to translate your organisation’s policy into practicable procedures and measures. The procedures manual describes the administrative organisation of your company, by which we mean the systematic collection, recording and processing of data for the following three components of your operational management: „ organisational governance of a payment institution; „ operation of a payment institution; „ accountability for operation of a payment institution; A procedures manual serves the following objectives.

  1. Transparency: it provides an overview of the structure of the administrative organisation. The procedures manual describes how processes are structured and the guidelines that apply.
  2. Efficiency and effectiveness: the procedures manual is the starting point for an administrative organisation based on efficient and effective processes.
  3. Knowledge transfer: the procedures manual can be used for training and induction of new staff members, while a clear and uniform description of processes will ensure a consistent approach throughout the organisation.
  4. Authorities and responsibilities: authorities and responsibilities within processes are clearly delineated. For example, signing authority. This will help mitigate risks.
  5. Control: the procedures manual contributes to a well-structured and adequately implemented internal control system.
  6. IT: the procedures manual provides basic input for IT systems, e.g. authorisations. 3.7 External audit This section does not apply to you if you only provide payment service type 8. The instruction to the external auditor to audit the annual accounts must at least include an instruction for a review and general assessment of the adequacy of the organisational structure and risk management. The external audit must also focus on the management of risks that may be of material influence on the company’s financial performance, position and continuity. The external audit must be integrated in the year￾end audit of the financial statements as much as possible. The external auditor’s report must include an opinion of the company’s operational management. For a complete application, please include the signed agreement with the external accountant or the draft engagement letter with your licence application. 3.8 Outsourcing As we are responsible for the prudential supervision of all activities and business processes of your company (also if these have been outsourced), it is important that you provide us with all information based on which we can assess whether all activities (including those that are outsourced) are performed in conformity with the law. Your company is permitted to outsource activities, unless doing so hampers adequate compliance with the applicable rules and regulations or business continuity. This is because your company must be able to continue its operations independently even when the outsourcing ends. For this reason, there are activities that you are not permitted to outsource, i.e. the duties

20 DNB Licence application for payment service providers and activities of the company’s day-to-day policymakers, including establishing policies and accountability for the policies pursued. In addition, you must clearly indicate whether (staff) members of your company also perform work for group entities (intra-group) and how the risk of potential conflicts of interests is mitigated. If intra-group outsourcing/group services are involved, we expect you to demonstrate through your outsourcing policy that your company is capable of making autonomous decisions and that you have a vote in decision-making on group services, for example, by participating in relevant group committees. We expect you to describe your role and responsibilities in such group committees. Furthermore, the outsourcing policy should include the intra-group escalation options applicable to your company in cases of, for example, conflicts of interests. The internal control function must have professional expertise, detailed knowledge of the structure of the organisation and must be available at all times. Outsourcing this function to a company that has no formal or de facto governance structure relationship with your company will consequently often be an obstacle to ensuring the quality of internal control. This means that if the internal audit function is outsourced, the activities must still be performed under your company’s management and supervision. Your company must at all times be able to render account of the structure and effectiveness of its operational management. The risk of conflicts of interests should be explicitly considered when determining which third party will be selected to perform the audit, and which staff member within the company will be made responsible for management and supervision. We expect you to provide insight into your company’s considerations in this regard. Outsourcing policy Your company must pursue an adequate policy and have adequate procedures and measures in place regarding permanent outsourcing of processes, and it must have satisfactory procedures and measures and sufficient expertise and information available to be able to assess the performance of activities that are outsourced on a permanent basis. This implies that your company must have sufficient local expertise to monitor, assess, control and manage the outsourced work. Your company must always enter into written agreements with the third parties to which it has outsourced activities on a permanent basis. Please include a copy of your outsourcing policy with your licence application. In order to be able to pursue an adequate policy with respect to activities that are outsourced on a permanent basis, it is important that your company takes into consideration the influence that outsourcing of activities has on sound business operations. For example, by having procedures and measures in place to deal with inadequate service provision by the third party or emergency situations. Payment institutions that outsource activities must systematically analyse the risks associated with outsourcing. Systematic risk analysis is an essential element for assessing whether or not activities are suitable for outsourcing. You must perform a separate risk analysis for each of the service providers concerned. The procedures manual must describe how the

21 DNB Licence application for payment service providers outsourcing risk analysis is compiled, and you must submit risk analyses for all outsourced material activities, i.e. activities that, if they are not completely or adequately performed, may seriously harm the company’s compliance with the requirements of its licence, its financial results, or the solidity or continuity of its payment services. Outsourcing agreement To assess outsourced activities adequately, your company must have sufficient information at its disposal about the company to which it outsources these activities. You must also have sufficient in-house expertise to be able to assess this information adequately. The outsourcing agreement must at least provide for the following: „ the exchange of information between the company and the third party about unlocking information required by the supervisory authorities as part of the performance of their statutory tasks; „ the option for your company to make changes at any time to how the third party performs the outsourced activities; „ the obligation incumbent on the third party to enable your company to keep meeting the requirements ensuing from primary and secondary legislation; „ the possibility for supervisors to perform, directly or by proxy, examinations on the premises of the third party; „ the manner in which the agreement is terminated and how, after termination, it is ensured that your company can again perform the activities concerned itself, or have such activities performed by another third party. These requirements also apply if the service provider to which your company has outsourced the activities has subcontracted these activities. And finally, when outsourcing activities the company must verify that the fact of outsourcing does not compromise its duties towards its customers and the legal rights of its customers. 3.9 International services Payment institutions that have their registered office in the Netherlands can operate in any other country of the European Economic Area (EEA) on the basis of the licence granted by DNB, without having to apply for a licence in the other EEA country concerned. Payment institutions are required to notify DNB of this. More information on the background and types of notifications can be found on our Open Book on Supervision Payment institutions: outgoing notifications. In anticipation of any international service provision and for the timely processing of any notifications, you must provide an explanation of how the company intends to extend its services to other Member States or to a third country outside Europe, e.g. through passporting, cross-border services, a branch or an agent. You must indicate whether your company or the group of which your company is part already operates internationally. as well as describe how you intend to monitor and check agents and branch offices as part of your company’s internal control system, with particular emphasis on the monitoring and control processes related to financial crime and compliance with sanctions legislation. If your company uses agents, we expect you to also provide an overview of the IT systems, processes and infrastructure used by these agents to perform activities on your behalf.

22 DNB Licence application for payment service providers 3.10 Information systems, infrastructure and security PSD2 requires a stronger focus on the management of operational and security risks. Subsections 3.10 to 3.15 set out our expectations regarding the management of these risks, which means there will be some overlap with the other subjects described in this section. You do not have to submit the same document again for each of these subsections, but we ask you to include clear references as to where the requested information can be found in your application. You company must have in place an information system and information infrastructure to support operational processes. They should meet all internal and external information requirements. There must be effective management of operational and security risks. The information system and infrastructure must be set up to ensure that transactions and entries in data files can always be retraced to authorised source files or data processing by authorised staff or systems. Electronic data processing (EDP) and the related infrastructure must be an integrated part of the organisation, and the data must comply with the requirements relevant to the nature of the activities and statutory regulations. A company using electronic data processing and offering EDP-based services must implement measures and procedures to ensure the integrity of the electronically processed data, protect the data from unauthorised access or processing and safeguard the availability of data and EDP. The description of measures and procedures to manage operational and security risks must address the following. a. The company’s IT strategy, IT policy and security policy. b. The IT landscape, the information systems and their infrastructure, including internal and external links. c. The information systems, infrastructure components and links that are classified as critical, including the applicable classification criteria and a substantiation. d. The operational and security risk management framework. e. The risk and risk management model, including a detailed risk analysis. f. Identification and classification of operational functions, processes and resources, with a focus on the availability, integrity and confidentiality of systems, infrastructure, data and processes. g. The measures in place to protect the data, information systems and information infrastructure as well as the integrity of these information systems, information infrastructure and data, using security measures and logical and physical access security, possibly including multiple layers of protection. h. Continuous monitoring and detection of internal and external threats and vulnerabilities that could have an impact on the information systems and the information infrastructure, and how this is approached. i. The policy, process (with its relevant procedures) and specification of logical access security, providing insight into the organisational segregation of duties with respect to the security of logical access to information systems and the information infrastructure. j. Continuous monitoring and detection of variations and unauthorised activity in the information systems and information infrastructure.

23 DNB Licence application for payment service providers k. Testing of security measures to assess their robustness and effectiveness, including regular vulnerability scans and penetration tests (at least once a year). l. The process with its relevant procedures for making changes to the information systems, information infrastructure and security measures, including the implementation of short-term emergency changes. m.The process providing continuous insight into the vulnerabilities at security and operational levels in IT and the financial sector that could impact the company’s information systems and information structure and (if necessary), sharing of insights with the sector. n. Training staff members in the area of security and information security. o. Informing users/customers about security and information security. p. The process with its relevant procedures for secure sharing of data and secure submission of obligatory reports. q. The process of independent assessment of the security measures by auditors with expertise in the area of IT security and payments, who are operationally independent within or with respect to your company. 3.11 Authentication The purpose of authentication is to establish the identities of payment service users and others. If your company has direct contact with payment service users, you must apply strong customer authentication (SCA). SCA means authentication based on combining two or more elements categorised as knowledge (i.e. something only the user knows), possession (i.e. something only the user possesses), and inherence (e.g. a user’s biometrical characteristics), resulting in a unique authentication code. The procedures manual must address the following aspects of authentication: „ The use and control of these customer authentication instruments „ The supporting processes and resources (hardware and software) „ The protection of the authentication code in accordance with Commission Delegated Regulation (EU) 2018/389, the European Regulatory Technical Standards (RTS) on strong customer authentication. The application must include a policy document describing for each individual payment instrument how a customer, when making a payment, can demonstrate that they are authorised to make that payment. This can be submitted as a separate document, or as part of the information security policy. If you believe your company is exempted from applying SCA, you must be able to substantiate this. When authorising a payment transaction, the unique authentication code generated specifically for the payment transaction must be linked to this payment transaction (i.e. the dynamic linking requirement laid down in the RTS). The procedures manual must describe your company’s process and security measures related to customer authentication. You must test the customer authentication process and security measures on a regular basis, and ensure that they are assessed and checked by auditors with expertise in the area of IT security and payments, who are operationally independent within or with respect to your company.

24 DNB Licence application for payment service providers 3.12 Secure communication Your company uses electronic (digital) means to communicate with third parties. This means you must take the necessary measures to safeguard the availability of communication and ensure data confidentiality and integrity. The procedures manual must describe the measures you have taken and the processes and procedures to manage them. As a payment service provider, you must ensure secure identification in the communication between the equipment of payers and payees used for accepting electronic payments. You must also ensure that the risk of communication towards unauthorised parties is limited as far as possible. You must describe how you do so in the procedures manual. As a payment service provider, you must have procedures in place to safeguard that all payment transactions and other interactions with payment service users: „ with other payment service providers „ and with other entities, including merchants, are traceable in the context of providing the payment service, so that all events relevant to the electronic transaction at all its different stages are subsequently known. You must ensure that all communication sessions with payment service users, other payment service providers and other entities (including traders) include each of the following elements: a. A unique session identifier. b. Security mechanisms for detailed transaction logging, including a transaction number, time stamp and all relevant transaction details. 3 The account holder’s name and account number do not qualify as sensitive payment data in relation to the activities of payment initiation service providers and account information service providers. c. Time stamps that are based on a time reference system and synchronised with an official time signal. Your company’s procedures manual must include a description of how this is ensured in your organisation. If your company uses cryptographic means, you should also describe the technologies used and how these means (e.g. keys and certificates) are stored and managed. 3.13 Data collection Due to the nature of the proposed activities, your company will be dealing with sensitive payment data, i.e. data that could be abused for fraudulent purposes. This in any event includes personal security details3 . Sensitive payment data must never fall into the wrong hands, which is why you must provide a description of your company’s process for storing, monitoring and tracing sensitive data and for restricting access to such data. You should include the following four elements in this description: „ A description of the data flows in proportion to your business model. „ A description of the storage process for collected data. If you provide type 7 services only, this is not required, since type 7 service providers are not permitted to store sensitive payment data. „ A description of the expected internal and external applications, including a description of any third parties involved in this, with respect to collected and stored data. If you provide type 7 services only, this is not required, since type 7 service providers are not permitted to store sensitive payment data.

25 DNB Licence application for payment service providers „ A list of the individuals, operational units and committees with access to the sensitive payment data, including explanatory notes. Please note that the list above is not exhaustive. In addition to the above, you must also submit your company’s privacy and data collection policy with your application. If your company is granted a licence, the following applies to your organisation with respect to data protection. „ If your company offers payment services types 1 to 7, you may only access payment service users’ personal details with their express consent, and only process and store these details to the extent that you need them for the provision of payment services4. „ Your company’s procedures manual must include a description of how this is ensured in your organisation, taking into account temporary storage of payment data, security and authentication data, and how consent is recorded. „ If your company offers type 8 payment services, you may only provide these services with the express consent of the payment service user.5 . „ Your company’s procedures manual must include a description of how this is ensured in your organisation, taking into account temporary storage of payment data, security and authentication data, and how consent is recorded. 4 See Section 26e of the Decree on Prudential Rules for Financial Undertakings (Besluit prudentiële regels Wft – Bpr) 5 See Section 26j of the Decree on Prudential Rules for Financial Undertakings (Besluit prudentiële regels Wft – Bpr) 3.14 Follow-up of incidents Operational or security incidents Operational or security incidents are events that endanger the availability of your company’s services, the confidentiality or integrity of the data entrusted to your company, or both. Given the impact of such incidents on your operational management, you must have measures in place to minimise the risk of such incidents occurring. This is why your company must have policy, procedures and measures in place to address operational or security incidents. The following procedures and measures must be described as a minimum. „ Incident recording. „ Classification mechanism based on criteria determined by law, distinguishing between major and non-major incidents and providing for an adequate analysis of the internal and external impact of incidents, including the impact for fellow payment institutions inside or outside the Netherlands. „ Notification to DNB of major incidents within four hours and in accordance with the set procedure and the required information. „ Procedure for updating DNB on the progress of resolving incidents. „ Performing a root cause analysis after incidents have been resolved. „ Fully informing DNB based on the prescribed procedure. „ Your company must have a complaints procedure enabling payment service users to report potential or actual security risks and incidents.

26 DNB Licence application for payment service providers We are obliged to notify the European Banking Authority (EBA) and the European Central Bank (ECB) of any operational or security incidents, and these bodies may contact your company directly on the basis of this information (see EBA￾GL-2017-10). You must describe your company’s policy, procedures and measures regarding operational and security incidents in the procedures manual. Your company is responsible for notifying any other relevant authorities (e.g. the Dutch Data Protection Authority) in the Netherlands in the event of operational or security incidents. Integrity incidents An incident is defined as behaviour or an event that poses a serious threat to ethical pursuit of business operations. Because of the repercussions that incidents can have on a company, it is important that you organise your operational management so as to ensure that the risk of incidents occurring is limited to the best possible extent. The company must be prevented from being implicated in criminal offences, or committing acts that conflict with commonly accepted practices. It makes no difference who commits said acts; they may include behaviour of staff members, executive directors, supervisory board members, or of natural or legal persons working for your company. This includes both displaying and refraining from specific behaviour. This is why your company must have procedures and measures in place to deal with incidents. This entails the following: „ Recording of incidents; „ Procedures for dealing with incidents; „ Supply of information to the supervisory authorities. Your incident records enable us to assess whether your company handles incidents in the appropriate manner. From your records, we should be able to distil the characteristics of the incident, the perpetrators causing the incident or aggravating the situation, and the measures taken. You must notify us promptly of any incidents. Fraud reporting Payment institutions are obliged to collect data on fraud and report these to DNB in a prescribed format and on a regular basis, i.e. you must submit an overview of quarterly fraud data every six months. Your company must have procedures and measures in place to record the correct data and meet the fraud reporting requirements. The procedures and measures must be described in the procedures manual. For this section, please refer to the Guidelines on fraud reporting on the EBA website (https:// www.eba.europa.eu/activities/single-rulebook/ regulatory-activities/payment-services-and￾electronic-money/guidelines-fraud-reporting￾under-psd2). 3.15 Business continuity management Your company must have a business continuity management (BCM) system in place to enable the recovery of its services following serious internal or external disruptions as soon as possible in accordance with the agreements made and socially expected recovery time. The BCM system must be described in the procedures manual and must address at least the following eight elements:

27 DNB Licence application for payment service providers „ The BCM policy, describing the organisation during disruptions, disruption classification, maximum recovery times for systems and processes, internal and external communication, escalation, notification of authorities, loss of data, etc. „ A business impact analysis, taking into account the internal and external impact of incidents. „ The measures in place to implement the policy and the agreements made, and how these measures were formulated. „ The various disruption scenarios in use. „ A communications plan. „ A crisis management plan. „ The human factor. „ A testing plan for the BCM system, setting out the method and frequency of testing, demonstrating that the company is able to comply with its own policy at all times 3.16 Sound remuneration policy As part of sound operational management, your company must pursue a sound remuneration policy that must be recorded in writing in a separate document (and not in the Procedures Manual). In short, the policy must include the requirement that remuneration does not contain incentives to take more risks than what is acceptable in view of the company’s solidity. The remuneration policy must describe any potentially negative incentives as part of risk management in a structured and logical way, and describe how your company prevents and mitigates these incentives. Obviously, developing a sound remuneration policy requires in-depth analysis of possibly inappropriate incentives contained in remuneration structures and components. This analysis should pay explicit attention to the incentives that may arise as a result of variable remuneration components. It could also cover positive incentives arising from clawback provisions. The description of your company’s remuneration policy must answer the following four questions: „ Is the fixed-to-variable remuneration ratio applied appropriately within the company? This includes the generally important aspects of remuneration policies, e.g. the nature of the company’s activities, the size of the company and the consequences for customer treatment. When formulating the appropriate ratio, your company must of course remain within the boundaries set by the bonus cap. „ What is the ratio between awarded remuneration and paid-out variable remuneration? „ What is the composition of variable remuneration? „ What are the criteria and performance on which variable remuneration is based? You should not just describe the performance and results of the individual staff members receiving the variable remuneration, but also the performance of their business unit, and that of the payment institution as a whole. Performance assessments of individual staff members must also include non-financial criteria, e.g. to what extent objectives such as the following have been achieved: strategic goals, customer satisfaction, compliance with risk management policies, compliance with internal and external rules, leadership, management skills, cooperation with other staff and business units, creativity, motivation, sustainability, and corporate social responsibility. Negative performance on non-financial criteria, especially in the case of unethical or non-compliant behaviour must cancel out positive results on financial criteria. In such cases, variable remuneration should be reduced to zero. At least 50% of variable remuneration must be based on non-financial

28 DNB Licence application for payment service providers criteria. Please note that variable remuneration is subject to a cap under Section 1:121 ff of the Wft. Please enclose your remuneration policy document as an annex to the application form. We also ask you to briefly state in your own words how your company’s remuneration policy does not encourage staff to take more risks than what is acceptable in view of the company’s solidity. 3.17 Oath or affirmation Your company must have procedures and measures in place to ensure that natural persons working in the Netherlands under the responsibility of your company, whose activities may have a material impact on the company’s risk profile, or who are directly involved in the provision of financial services, take the oath or affirmation in conformity with the 2015 Regulation on the Financial Sector Oath or Affirmation (Regeling eed of belofte financiële sector 2015). 3.18 Education and training Adequate implementation of processes and procedures largely depends on the level of knowledge and experience of staff. This is why knowledge and experience of risk management (including money laundering and terrorist financing) are important preconditions for developing an adequate control framework. Staff training courses are important instruments to communicate and embed knowledge of the Anti-Money Laundering and Anti-Terrorist Financing Act (Wet ter voorkoming van witwassen en financieren van terrorisme -Wwft) and the Sanctions Act 1977 (Sanctiewet 1977 - SW) and integrity principles and procedures. Your company is required to offer its staff training courses to ensure that staff members are acquainted with the provisions of the Wwft and the SW, to enable staff to perform customer due diligence fully and correctly and to recognise unusual transactions. These programmes should focus on money laundering and terrorist financing techniques, methods and trends, on the international context and standards, and on new developments in this area. To enable your staff members to keep abreast of new developments and to improve awareness in the long term, your company must provide training programmes at regular intervals and at different levels, rather than as one-off sessions. The compliance function is also advised to attend additional training programmes to keep up to date on new developments in national and international legislation and regulations, and risks of money laundering and terrorist financing. Please enclose your company’s training programme with the application form. We also ask you to submit a description of how your company has organised its training scheme to guarantee sound business operations. The description can be part of the company’s procedures manual or be included in a separate document. Please state in the application form where we can find the relevant information.

29 DNB Licence application for payment service providers 4 Operational management set-up for ethical business operations Ensuring ethical business operations is one of the pillars of confidence and as such it is a precondition for your company’s proper functioning. It is essential that you prevent your company from becoming involved in unlawful or socially unacceptable acts. Management of integrity risks is the key issue here, with a focus on countering financial crime. Money laundering, terrorist financing and conflicts of interest are key examples of financial and economic crime. The requirement of ethical business operations is based on Sections 3:10 and 3:17 of the Wft as further elaborated in the Decree on Prudential Rules for Financial Undertakings (Besluit prudentiële regels Wft – Bpr). The applicable integrity legislation is the Anti-Money Laundering and Anti-Terrorist Financing Act (Wet ter voorkoming van witwassen en het financieren van terrorisme - Wwft) and the Sanctions Act (Sanctiewet 1977 – Sw). Your company must pursue an adequate integrity policy to ensure ethical business operations. This integrity policy must be detailed and implemented in clear and readily accessible procedures and measures, recorded in a procedures manual. The regulatory framework for adequate integrity policies is risk-based, meaning that your company must implement all measures that the law requires. The focus of these measures depends on the risks that your company is exposed to. They may e.g. follow on from the nature and background of your customers, the type of product (iDEAL, card terminal, money transfer, etc.) or the type of service (types 1 to 8). You must assess the risks that your company is exposed to and formulate appropriate mitigating measures. 6 We have prepared Q&As on customer due diligence for providers of type 7 and 8 services. You will find these Q&As on our PSD2 web page: https://www.dnb.nl/en/sector-information/supervision-sectors/payment-institutions/integrity-supervision/ 7 We have prepared Q&As on customer due diligence for providers of type 7 and 8 services. You will find these Q&As on our PSD2 web page: https://www.dnb.nl/en/sector-information/supervision-sectors/payment-institutions/integrity-supervision/ The following points should be addressed in this assessment: „ Systematic integrity risk analysis „ Prevention of conflicts of interest „ Dealing with and reporting of incidents „ Propriety of staff in integrity-sensitive positions; „ Customer due diligence6 „ Sanctions Act 1977 (Sanctiewet 1977 – Sw) „ Transaction monitoring and reporting of unusual transactions7 „ Complaints procedure These points are explained in greater detail below. National and European regulations regarding payment services and risks such as money laundering and terrorist financing are constantly changing. You are responsible for updating your policy and procedures in accordance with the applicable rules and regulations. 4.1 Systematic integrity risk analysis (SIRA) Your company’s integrity policy and its implementation starts with identifying your integrity risk exposure. Such a systematic integrity risk analysis (SIRA) is a precondition for ensuring ethical operational management. The analysis must be verifiable, i.e. recorded in a separate document, and the integrity policy must be based on the outcome of the SIRA, and Your company must use a comprehensible quantification method. The SIRA is based on gross (inherent) and net (residual) risks and analyses the likelihood and impact of these risks. The size of net risks must be clear and the measures and procedures must have a plausible impact.

30 DNB Licence application for payment service providers The SIRA must at any rate include an analysis of the following risks, based on different scenarios: conflicts of interests, money laundering, terrorist financing, non-compliance with sanctions legislation and internet fraud and scams. Your company’s SIRA must also include an analysis of risks associated with the products and services of your customers (merchants or natural persons) and you must include this in the customer profiles that will be used. You are also required to pay extra attention to on-line customer acceptance (if applicable). This inherently carries high risk and your analysis must specify the measures with which your company intends to offset this elevated risk. Your procedures and measures must be verifiably connected with the specific risks identified in the SIRA. The controls set out in the SIRA must be in line with the nature, size, complexity and risk profile of your company’s operations. You will find more information on the SIRA in our Good practices for preparing an adequate SIRA: https://www.dnb.nl/media/aeudln5i/dnb-sira-gp￾2025-en.pdf. In addition to a complete and substantiated SIRA, your licence application must also include a (policy) document setting out the governance for the drafting, periodic review and updating of the SIRA. 8 Section 11 of the of the Decree on Prudential Rules for Financial Undertakings (Besluit prudentiële regels Wft) This document must cover the following elements:

  1. The steps of the SIRA process
  2. Responsibility for the implementation of the SIRA process
  3. Ad hoc and periodic review and updating frequency (at least annually)
  4. Involvement of business functions in drafting and updating the SIRA
  5. Ultimate responsibility for the SIRA (which should lie with your company’s management board/day-to-day policymakers) 4.2 Preventing conflicts of interests Conflicts of interest or the semblance thereof may negatively affect your company as well as its customers. Your company must therefore have procedures and measures in place to prevent conflicts between its own business interests and the private interests of specific groups8, i.e. „ policymakers „ group directors „ supervisory board members, and „ other staff members or individuals employed on a permanent basis by the payment institution. This policy should make clear how you approach e.g. „ personal, professional, and financial interests in relation to contacts with customers and other stakeholders (such as suppliers and outsourcing partners) „ handling information and confidential information „ customer relationship management „ private financial transactions, and „ secondary activities.

31 DNB Licence application for payment service providers The policy document must also set out the following: „ Possible types of conflicts of interest within your company (e.g. conflicts of interests between staff member and payment service provider, staff member and customer, staff member and vendor, business line manager and head of compliance, ‘dual hatting’ among directors and key function holders, director and director￾majority shareholder) „ Reporting procedure for conflicts of interests, including reporting lines „ Responsibility for handling conflicts of interests (e.g. the manager of the relevant business line and/or the head of compliance). 4.3 Propriety in integrity-sensitive positions In addition to the positions of managing director or member of the supervisory body, there are other positions that may influence ethical business operations. These are known as integrity-sensitive positions. You must determine which positions in your company qualify as integrity-sensitive, and thoroughly screen the staff members holding these positions for propriety. This also applies to temporary staff. The following positions always qualify as integrity-sensitive: „ management directly below policymakers and co-policymakers „ positions with powers that pose real risks to ethical business operations Your licence application must include a document showing that your company has a policy regarding the propriety of staff in integrity￾sensitive positions that must meet the following requirements: „ It must clearly describe the positions to which it applies. „ It describes the level of screening applied (on an ongoing basis). „ If it states that all positions are considered integrity-sensitive in the first phase after licensing, it should also state when or under what circumstances this phase ends and which positions are then considered integrity-sensitive. „ If the policy and/or procedures indicate that screening is applied on an ongoing basis, the frequency and method of screening must also be indicated (e.g. weekly via an automated sanctions screening system). „ It must also specify the relevant sanction lists, BKR, VOG, etc. against which the positions are screened. 4.4 Customer due diligence You are not permitted to start providing services to customers before you have identified and verified the customer and the ultimate beneficial owner (UBO), i.e. before you have performed customer due diligence. Your procedures manual must clearly set out the procedures and measures on customer due diligence. Procedures and measures relating to customer acceptance must be in accordance with the company’s integrity policy and the outcome of the SIRA. The frameworks of the Wft (ethical operational management) and the Wwft assume that a company classifies its customers into risk categories, based on the nature and size of risk exposure. These risk categories vary from low to high risk, and the classification should be based on objective and identifiable indicators. The higher the risks, the more efforts your company should make to mitigate them. You must also indicate which risks you find unacceptable.

32 DNB Licence application for payment service providers When performing customer due diligence, you must take account of the following points. „ Your company must verify the identity of all customers based on independent and reliable documents. If legal entities are concerned this also includes their representatives and ultimate beneficial owners (UBOs). „ Your company is sufficiently familiar with the customer’s or legal entity’s ownership and governance structure. „ Your company must be well aware of, and must have adequately documented, why and with what intention the customer wants to use your company’s services, and it must see to it that this is incorporated into the customer’s risk profile. „ All customers must undergo politically exposed person (PEP) screening and sanctions screening. „ Your company must consider the policy towards high-risk countries (including a list). „ Your company must consider the exit policy (e.g. for dealing with unreachable an uncooperative customers). „ Your company must consider the policy on periodic reviews. „ Your company is required to keep all such information in readily accessible form for at least five years after it has ceased providing services, or terminated the business relationship. „ All data and files relating to the customer and the ultimate beneficial owner must be kept in a central place and can be accessed by compliance and other relevant staff. Your company must also record when enhanced customer due diligence is required and which measures it intends to take in such cases, and document whether customers, prospective customers or ultimate beneficial owners are politically exposed persons. Your company must classify customers into risk categories, stating its reasons for allocating customers, products or services to specific risk categories. This classification must be adequate and in line with your company’s SIRA. Customers are accepted subject to screening against sanctions lists, PEP lists and any other relevant lists. Your company must record positive matches in the relevant customer file and take action where needed. These matches must also be mentioned in the customer’s risk profile and must be reported to us. And finally, an exit policy must be put in place for customers who cannot or do not want to be identified, or whose identity cannot be verified in the prescribed manner. When such cases occur, they must be verifiably followed up. The procedures and measures must document how and by whom customer due diligence is to be performed, as well as the responsibilities of the first-, second- and third-line functions. It must be ensured that the relevant staff members are aware of the internal and statutory requirements imposed on customer due diligence. Customer acceptance must be approved by authorised staff or management based on the four-eyes principle. See our Wwft Q&As and Good Practice and the section on sanctions regulations in the former DNB Guideline on the Anti-Money Laundering and Anti-Terrorist Financing Act (https://www.dnb. nl/media/meidddba/dnb-qas-en-good-practices￾wwft.pdf) for more guidance on this topic. Your licence application must include your company’s policy regarding the above-mentioned elements, for example as part of the procedures manual. 4.5 Sanctions Act 1977 (Sanctiewet 1977 – Sw) Your procedures manual must include your policy and procedures on sanctions legislation. These procedures must guarantee the existence of a comprehensive and up-to-date inventory of

33 DNB Licence application for payment service providers services provided, broken down by countries, natural persons, legal entities and groups governed by sanctions legislation. You must also have a procedure in place for the receipt and internal distribution of sanctions lists (at least with respect to the Netherlands sanctions lists and the EU regulations). These procedures and measures must ensure that the customer base is regularly screened on matches with the entities targeted by sanctions legislation. The procedures must provide for risk￾based monitoring of domestic and international services. The procedures and measures take account of the standards and objectives of the various sanctions regulations (governing sanctions against persons/ entities or against countries). The procedures and measures must be structured to ensure that if a match is detected financial assets may be frozen, or financial resources or services can be prevented from being made available to persons or entities mentioned on the sanctions list. Your company must have adequate measures in place to guarantee that any matches are reported without delay to the responsible central person or department and, if acknowledged as a match, reported to DNB. For more guidance on this topic, see https://www.dnb.nl/en/sector-information/ open-book-supervision/laws-and-eu-regulations/ sanctions-act-1977/the-section-on-sanctions￾regulations-in-the-former-dnb-guideline-on￾the-anti-money-laundering-and-anti-terrorist￾financing-act-and-sanctions-act/ and https://www.dnb.nl/en/sector-information/ open-book-supervision/laws-and-eu-regulations/ sanctions-act-1977/the-section-on-sanctions￾regulations-in-the-former-dnb-guideline-on￾the-anti-money-laundering-and-anti-terrorist￾financing-act-and-sanctions-act/. Your licence application must include your company’s policy regarding the above-mentioned elements, for example as part of the procedures manual. 4.6 Transaction monitoring and reporting of unusual transactions Your company must have procedures and processes in place to monitor customers’ accounts, activities and transactions so as to gain and retain insight into the nature and background of customers and their financial behaviour, and to detect non-standard transaction patterns, including unusual transactions and transactions that by their nature entail increased risk of money laundering or terrorist financing. You must have procedures and processes in place specifying how transactions are monitored, which alerts and red flags are used, and how to act if transactions are made that may qualify as unusual, and you must make motivated and appropriate choices between electronic monitoring and manual monitoring. Electronic monitoring may be applied for large numbers of transactions. You must have policies and procedures in place to report detected unusual transactions to FIU￾Netherlands without delay. For more guidance on this topic, see https:// www.dnb.nl/en/sector-information/open-book￾supervision/open-book-supervision-sectors/ payment-institutions/integrity-supervision/. Your licence application must include your company’s policy regarding transaction monitoring and reporting of unusual transactions, for example as part of the procedures manual.

34 DNB Licence application for payment service providers 5 Fit and proper assessment of policymakers and co-policymakers 5.1 Fitness of policymakers The policymakers9 in your company must be fit to occupy this position. We therefore recommend that you nominate individuals whom you expect to pass DNB’s fit and proper assessment. When assessing fitness, we determine whether an appointee has sufficient relevant knowledge and skills, and displays the required professional behaviour to perform the job, and establish this based on education, work experience and competences. As the assessment is linked to position, we consider „ the details of the candidate’s proposed position, „ the nature, scope, complexity and risk profile of the company, and „ the composition and performance of the policymaker collective. We apply the Policy Rule on Suitability 2012. For more information, please refer to the Fact Sheet on fitness on our website: Initial assessment – assessing fitness (https://www.dnb.nl/en/sector￾information/open-book-supervision/open-book￾supervision-themes/fit-and-proper-assessments/ and https://www.dnb.nl/en/sector-information/ open-book-supervision/open-book-supervision￾themes/fit-and-proper-assessments/initial￾assessment/initial-assessment-assessing￾fitness/). Supervisory boards (whether or not required by DNB) must act independently, as part of the company’s sound and ethical operational management. For more information, please refer to our Q&A on supervisory board independence for payment institutions 9 The company’s policymakers are the members of its Management Board and – if applicable – the members of its Supervisory Board. Co-policymakers are not subject to the fitness assessment. The section on “Propriety of policymakers and co-policymakers” below sets out which staff members qualify as co-policymakers. (https://www.dnb.nl/en/sector-information/ open-book-supervision/open-book-supervision￾themes/fit-and-proper-assessments/initial￾assessment/initial-assessment-assessing-fitness/). You can use the Initial assessment application form available from our Digital Supervision Portal (DLT) to present an appointee for assessment. We frequently see that application forms are not filled in completely, which causes unnecessary delays. On our website, you can find tips on how to prepare for the assessment: Fit and proper assessments (https://www.dnb.nl/en/ sector-information/open-book-supervision/ open-book-supervision-themes/fit-and-proper￾assessments/). Please note that for management board and supervisory board members a maximum number of supervisory roles applies under Book 2 of the Dutch Civil Code. 5.2 Propriety of policymakers and co-policymakers The propriety of the policymakers and co-policymakers in your company (management and supervisory board members and management of the customer accounts foundation) must be beyond doubt. Individuals who are able to exercise actual significant influence on the company’s day-to-day management are designated as co-policymakers. We verify whether the propriety of the appointee is beyond doubt, which involves ensuring their intentions, actions and antecedents do not stand in the way of performing their duties. In particular,

35 DNB Licence application for payment service providers we review criminal, financial, tax compliance, supervisory, tax administrative law antecedents and other relevant information. In principle, propriety assessments are a one￾time procedure. Appointees who have passed the assessment will not require reassessment. Our decision will stand unless a change in the relevant facts or circumstances provides reasonable grounds for a propriety reassessment. A propriety assessment is related only to the candidate individually. This means that – unlike in initial fitness assessments – our decision does not depend on circumstances such as the composition of the management board, the type of company that the proposed appointment pertains to or the specific post the appointee will take up. Propriety assessments are performed based on information provided by the company, and our review of that information. For more information, see the fact sheet on initial propriety assessments (https://www.dnb.nl/ en/sector-information/open-book-supervision/ open-book-supervision-themes/fit-and￾proper-assessments/initial-assessment/initial￾assessment-propriety-assessment/). The initial assessment applications mentioned in 5.1 and 5.2 must be submitted together with your licence application.

36 DNB Licence application for payment service providers 6 Two day-to-day policymakers working from the Netherlands The day-to-day management of your company must be in the hands of at least two natural persons. These two individuals must work from the Netherlands, in order to ensure compliance with the four-eyes principle, or the principle of dual day-to-day management. The rule that two or more natural persons must be responsible for the day-to-day management of a payment institution, guarantees continuity and observance of the quality standard of the company’s operations and services.

37 DNB Licence application for payment service providers 7 Transparent control structure Your company must have a transparent control structure. In short, this means that its formal control structure must be the same as the actual one. The control structure must not obstruct adequate supervision. This occurs if, as a result of the governance structure, individuals are employed by the company who are subject to the laws of non-EU states. The aim of this statutory provision is to prevent the organisational structure within which the activities of the control structure are performed from deviating sharply from the legal structure in which the activities are embedded. An organisational structure of this kind impedes adequate supervision of your company. This includes identifying your company’s risk exposure, or assessing whether its operational management is sound and prudent. Please provide a diagram of the legal structure (UBO, parent company, any subsidiaries and affiliated companies) of which your company (as a payment institution) is a part. It must reflect the actual situation clearly and accurately. The diagram must include the identities of the persons and entities possessing a qualifying holding in your company, as well as the size of such holdings. Owners of a qualifying holding include natural persons or legal entities that have a direct or indirect shareholding or degree of control in the company of 10% or more. The overview must also show the identity of the ultimate beneficial owner (UBO), and the managing directors of all legal entities and companies that are part of the group. Group relationships If your company is part of a national or international group or a group of affiliated companies operating within or outside the EU, we ask that you provide a description of the group’s decision-making tree and the role that your company plays in this.

38 DNB Licence application for payment service providers 8 Qualifying holdings This section does not apply to your company if you only provide payment service type 8. Companies wanting to acquire or enlarge a qualifying shareholding or a controlling interest in your company must obtain our prior permission. They must do so by applying for a declaration of no-objection (DNO) as referred to in Section 3:95 of the Wft. What do we mean by a qualifying holding? A qualifying holding, which is subject to a declaration of no objection (DNO), applies in the following cases. „ A legal entity or natural person holds or intends to acquire a direct or indirect holding representing 10% or more of your company’s issued share capital. „ A legal entity or natural person can exercise directly or indirectly 10% or more of the voting rights in your company, or have comparable control. In determining the number of voting rights of holders of participating interests in a company, we also take into account the votes that the holder has or is taken to have. Control comparable with voting rights may comprise special rights in respect of appointment, dismissal or suspension of management or supervisory board members of your company. Separate DNO procedure Before your company can be issued a licence, you must have all qualifying holdings approved by a DNO. To issue DNOs for qualifying holdings, we need relevant details from the qualifying shareholders. Note: the qualifying shareholders must submit these details by means of a separate form, available from the DLT. The DNO procedure runs parallel to the licence application. For complex shareholder structures, e.g. if more parties are required to submit DNO applications at the same time, we recommend that you contact us first. Please email us at markttoegang@dnb.nl. Consideration period The statutory consideration period for a DNO application is 62 business days. This may be suspended for up to twenty or thirty days if we need further information to consider your application. The consideration period starts on the first business day after we have received the complete DNO application (all required information). Costs We charge a fee for considering applications for licences or DNOs. The fees charged are listed in Annex I to the Financial Supervision Funding Act (Wet bekostiging financieel toezicht). The fees charged depend on the number of hours spent on processing the application. The fee for a DNO application is charged to the party acquiring or increasing the qualifying holding and applies regardless of whether DNB issues or rejects the application, the applicant withdraws the application during the procedure, or we cease consideration during the procedure.

39 DNB Licence application for payment service providers 9 Securing the funds of payment service users This section does not apply to you if you only provide payment service types 7, 8 or both. If your company provides payment services 1 to 6, you must ensure that the funds of payment service users remain separated from your company’s own funds. This prevents the payment service users’ funds from being seized by creditors in the event of bankruptcy, for example. Your company has three options for securing these funds. Method 1: customer accounts foundation The funds are paid into a separate account that cannot be touched by your company’s other creditors. In practice, this means that a separate, independent custodian must be appointed to manage the funds entrusted by payment service users – known as a customer accounts foundation. In order to guarantee as much as possible the independence of the customer accounts foundation, the foundation must meet the following conditions. „ The propriety of the customer accounts foundation’s management board members must be beyond doubt (see section 5.2), which means they must be assessed for propriety as part of the licensing procedure. „ Appropriate and concise description of objectives: the articles of association clearly and accurately describe the objective of the customer accounts foundation, i.e. receiving, managing and distributing customer funds. „ No commercial activities: following from its objective, the customer accounts foundation is not permitted to develop commercial activities, issue loans or enter into other financial commitments. This will prevent claims from being made on the foundation by third parties. „ Prudent handling of payment service users’ liquid assets: the company must also ensure that the liquid assets of the customer accounts foundation at any time at least equal the company’s liabilities to the payment services users (reconciliation). „ The payment institution must guarantee – without restrictive conditions – that the customer accounts foundation has sufficient funds available to make payments to payment service users in a timely manner. If you opt for this method, we expect you to submit a statement specifying to what extent your company complies with Article 10 of PSD2. You must also include a list of the persons having access to the protected accounts and their positions. Together with your licence application, you must submit proof of the opened bank account or a bank-signed statement (“commitment letter”) confirming that the customer acceptance procedure has been completed and that the bank account has been opened and blocked or frozen until the license is granted. You must also include a description of the accounting, coordination and payment autorisation processprocess for safeguarding that the funds of payment service users are protected, in these users’ interests, from claims of other creditors of the payment institution, especially in the event of insolvency. Method 2: segregated assets account The second method to secure payment service user funds is to use a segregated account that is designated by law to keep third-party funds outside the assets of the payment institution. This protects the assets of payment service users from claims by creditors of the payment institution, for example in the event of

40 DNB Licence application for payment service providers bankruptcy. The segregated account is held in the name of a duly authorised professional or other entity that is legally authorised to manage a segregated account. The account must comply with the following requirements: „ Segregation of third-party assets: The segregated account ensures that the assets of payment service users cannot be recovered by creditors of the payment institution. „ Restriction of commercial activities: The segregated account may only be used to receive, manage and pay out third-party funds. No other activities may be conducted, no loans may be issued and no other financial commit￾ments may be entered into using this account. „ The management activities for the segregated account and the payment activities of the company must be strictly segregated, to avoid potential conflicts of interests. As with the customer accounts foundation, we expect your company to be able to demonstrate how the requirements of Article 10 of PSD2 are complied with and how access rights to the segregated account are regulated (which persons have access, their positions, etc.). You must also include a description of the accounting, coordination and payment authorisation process for safeguarding that the funds of payment service users are protected, in these users’ interests, from claims of other creditors of the payment institution, especially in the event of insolvency. Together with your licence application, you must submit proof of the opened bank account or a bank-signed statement (“commitment letter”) confirming that the customer acceptance procedure has been completed and that the bank account has been opened and blocked or frozen until the license is granted. Method 3: insurance policy or comparable guarantee If you opt for method 2, we require a statement that the funds entrusted are covered by an insurance policy, or a comparable guarantee from an insurance company or a bank that is not part of the same group as your company. The policy or guarantee covers the risk that you fail to meet your obligations with respect to the funds. We also require a detailed description of the reconciliation process demonstrating that the insurance policy or guarantee offers sufficient coverage and quality to ensure that your company is able to meet its obligation to secure funds at all times.

41 DNB Licence application for payment service providers 10 Minimum own funds and solvency 10.1 Minimum own funds This section does not apply to you if you only provide payment service type 8. When applying for a licence, your company must at least have own funds on a par with the highest outcome of the following two calculations. Your company’s initial capital amounts to €125,000 for the provision of payment services „ 1 to 5, or „ 1 to 5 with 6 and/or 7 and/or 8. €350,000 for companies applying for a licence to operate as an electronic money institution. €50,000 for the provision of payment service „ 7, or „ 7 with 6 and/or 8 €20,000 for the provision of payment service „ 6, or „ 6 and 8. Your company’s own funds must not fall below the required amount of initial capital. You must provide detailed information on your company’s own funds with your application. It is important that you provide evidence of the paid-up own funds when submitting your application: „ For existing companies, we need a certified overview of accounts or extract from the public register stating the capital position of the applicant. „ For companies still in the process of incorporation, we need a statement from a bank that the funds have been deposited in the applicant’s bank account. Please take account of the eligible capital instruments when calculating your required actual own funds. These are the capital instruments referred to in Article 26 of the Capital Requirements Regulation (CRR). 10.2 Required actual own funds as part of solvency This section does not apply to your company if you only provide payment services type 7, 8 or both. As part of solvency requirements, your company must hold a sufficient amount of actual own funds for the purposes of the solvency test. The method to be used for calculating minimum actual own funds is determined based on the payment services that your company provides. The minimum level of actual own funds is generally calculated based on method B. In method B, the company’s actual own funds depend on the volume of payments made. However, we would ask you to submit calculations based on all three methods A, B, and C. The amount of actual own funds for electronic money institutions is calculated by a combination of methods B and D, where the latter is 2% of the average outstanding amount in electronic money. For more information, see the Guide for prudential reporting for payment institutions on our website (https://www.dnb.nl/en/login/dlr/supervisory￾reports/payment-institutions-and-electronic￾money-institutions/). The calculation and control of own funds is included in the prudential reporting templates. You can find these under ‘User documentation’. Please complete the templates for the three years ahead in full, in line with your financial projections (see Section 3). We want to remind you to take account of a number of deductible items when calculating your required actual own funds. These are the deductible items referred to in Article 36 et seq. of the Capital Requirements Regulation (CRR). Intangible fixed assets, for instance. These assets are regarded as “soft” assets that offer hardly any buffer against losses in times of stress.

42 DNB Licence application for payment service providers Other deductible items include earnings made in the current financial year that have not yet been confirmed by the auditor and deferred taxes encumbering future earnings. We would ask you to pay close attention to this, as we find these items are often overlooked. For more information, see the Guide for prudential reporting for payment institutions on our website (https://www.dnb.nl/en/login/dlr/supervisory￾reports/payment-institutions-and-electronic￾money-institutions/). Please note that when submitting the license application, proof that the statutory minimum capital has been deposited must be provided.

43 DNB Licence application for payment service providers 11 Liability insurance This section does not apply to you if you only provide payment services type 7, 8 or both. Please note: if your company also holds or is applying for a licence for services 1 to 6, the liability insurance requirement applies in addition to the minimum own funds and actual own funds requirements. If your company intends to offer payment initiation services or account information services, you are required to take out professional liability insurance or a comparable guarantee. You can find more information on the comparable guarantee in our Q&A on alternatives for professional liability insurance (https://www.dnb.nl/en/sector￾information/open-book-supervision/laws-and￾eu-regulations/psd2/alternative-for-professional￾indemnity-insurance/). The liability to be insured and level of coverage depends on the type of service provision. For example, for providing payment initiation services (type 7) you must be covered against non-permissible payment transactions and non-performance, inadequate performance or late performance of payment transactions. For providing account information services (type 8), you must be covered against claims from the payment service provider holding the account in relation to unauthorised or fraudulent use of account information. Minimum level of coverage The minimum level of coverage is calculated based on the following formula: Minimum level of coverage = the amount appropriate to the risk profile + the amount appropriate to the type of activities + the amount appropriate to the size of activities. Risk profile The amount appropriate to the risk profile can be calculated by taking the total value of reimbursement requests by payment service users and/or account holding payment institutions over the past 12 months. If your company was already active in the past 12 months and no such requests were made, you may enter 0 here. If your company did not yet provide services in the past 12 months, you should enter an estimated aggregate value of the predicted reimbursement requests over a 12-month period. If you do not enter an estimate or if the predicted value is EUR 50,000 or lower, we will depart from a notional amount of EUR 50,000. The risk profile includes the number of initiated transactions or the number of consulted accounts over the past 12 months. For payment initiation service providers this is calculated as follows: „ 40% of the first 10,000 initiated transactions „ plus 25% of the number of initiated transactions between 10,000 and 100,000 million „ plus 10% of the number of initiated transactions between 100,000 and 1 million „ plus 5% of the number of initiated transactions between 1 and 10 million „ plus 0.025% of the number of initiated transactions over 10 million. If your company is not yet active, the predicted number of initiated transactions can be taken. If you do not enter an estimate or if the predicted number is 50,000 or lower, we will set the number at 50,000 transactions. The same calculation method is applied with respect to the number of consulted accounts by an account information service provider. The number of initiated transactions can be read as the number of accounts consulted over the past 12 months.

44 DNB Licence application for payment service providers Type of activities The amount appropriate to the type of activities can be found as follows: if you are only applying for a licence for type 7 or 8 services, you can enter 0 here. If your company also holds or is applying for a licence for services 1 through 6, the indemnity insurance requirement applies cumulatively to the initial capital and own funds requirements. If your company also conducts other business activities in addition to providing payment services as referred to in Annex 1 of PSD2, a value of €50,000 is added to the formula unless your company can demonstrate, either by holding a guarantee or because the payment service provision activities are incorporated in a separate entity, that the risks do not impact service provision. Size of activities For payment initiation service providers, the amount appropriate to the size of activities is calculated as follows: „ 40% of the share of the total value of aggregate transactions over the past 12 months (N) between €0 and €500,000 „ Plus 25% of the part of N between €500,000 and €1 million „ Plus 10% of the part of N between €1 million and €5 million „ Plus 5% of the part of N between €5 million and €10 million „ Plus 0.025% of the share of N over €10 million. If your company provides account information services, the amount to be entered is calculated as follows: „ 40% of the share of the total number of users over the past 12 months (N) between 1 and 100 „ Plus 25% of the portion of N between 100 and 10,000 users „ Plus 10% of the portion of N between 10,000 and 100,000 users „ Plus 5% of the portion of N between 100,000 and 1,000,000 users „ Plus 0.025% of the share of N over 1 million users. If your company did not yet provide services in the past 12 months, you should enter estimated values and/or numbers. If you do not have an estimate available, or if the estimate is 50,000 or lower, you should enter 50,000. The above calculations are based on the EBA’s ‘Final Guidelines on Personal Indemnity Insurance under PSD2’, which can be found on the EBA website. With your licence application, in addition to the aforementioned information and documents, you must also submit a copy of the insurance policy with confirmation from the insurer that the policy meets the condition set out in the revised Payment Services Directive (EU) 2015/2366 (PSD2).

45 DNB Licence application for payment service providers Annex Overview of documents to be submitted with your licence application (non exhaustive) If you do not yet have access to e-Herkenning and the Digital Supervision Portal (DLT), this overview lists all required annexes referred to in the application form. Please note that this list is neither exhaustive nor detailed regarding all questions and explanations included in the application form. We recommend that you apply for e-Herkenning as soon as possible (possibly with an authorisation for one or more additional persons) so that you can consult a copy of the application form at all times. Plans „ Programme of operations and business plan „ Recovery and exit plan, including scenario analyses „ Marketing plan Overviews „ Organisation chart „ Diagram of the legal structure Analyses „ General risk analysis „ Systematic integrity risk analysis (SIRA) „ Business impact analysis „ Identification and classification of operational functions, processes and resources, with a focus on the availability, integrity and confidentiality of systems, infrastructure, data and processes. „ Completed FIN&CO REP payment institutions Excel template for the next three years (does not apply to service 7 and 8) Agreements „ A copy of the engagement agreement issued to the auditor or audit firm (not applicable to type 8) „ Copies of any outsourcing agreements Policy documents „ Risk management framework „ Compliance + compliance function charter „ Internal audit function + internal audit function charter „ Outsourcing „ Incidents „ Business continuity management „ Remuneration policy „ Prevention of conflicts of private interests „ Integrity-sensitive positions „ Customer due diligence „ Sanctions regulations „ Monitoring and reporting of unusual transactions „ Training plan Miscellaneous „ Recent extract from the Trade Register of the Chamber of Commerce „ Certified copy of the company’s articles of association „ Copy of the company’s updated shareholders’ register „ Funds flow chart (not applicable to types 7 and 8) „ List of outsourced activities „ Procedures manual (translation of policy into procedures and measures) „ Liability insurance (if applicable) „ Audited financial statements or auditor’s opinion regarding compliance with the own funds and/or solvency requirement „ Proof that the statutory minimum capital has been deposited „ If there is a customer accounts foundation:

  1. An extract from the Trade Register of the Chamber of Commerce of the customer accounts foundation.
  2. A certified copy of the articles of association of the customer accounts foundation.

46 DNB Licence application for payment service providers 3) Details of the agreements made between the company and the customer accounts foundation or a copy of the agreement between the company and the customer accounts foundation. 4) A statement from your company certifying that the customer accounts foundation meets specific conditions. 5) Proof of an opened bank account or a bank￾signed statement (“commitment letter”) confirming that the customer acceptance procedure has been completed and that the account has been opened and blocked or frozen until the license is granted. (not applicable to types 7 and 8) „ In case of a segregated assets account, proof of the opened segregated account or a bank￾signed statement (“commitment letter”) confirming that the customer acceptance procedure has been completed and that the bank account has been opened and blocked or frozen until the license is granted. „ If there is an insurance policy or comparable guarantee: a copy of this policy or guarantee (not applicable to types 7 and 8) „ Documentation showing the company’s own funds, e.g. certified financial statements including the external auditor’s opinion, memorandum of association, a bank statement showing the deposit of a specified amount of capital (not applicable to type 8) „ For existing companies you should include audited financial statements over the past three years, or an overview of the financial situation if the company has not yet issued financial statements (not applicable to types 7 and 8) „ Indemnity insurance policy or comparable guarantee (including terms and conditions) (not applicable to types 1 to 6) „ Calculation showing that the minimum level of coverage complies with EBA Guideline CB/2016/12 (not applicable to types 1 to 6) Please note that you must also submit the following applications separately through the DLT in parallel to the licence application. Fit and proper assessments for all relevant persons, with a separate form for each person to be assessed „ Application form for Initial Assessment „ Initial Assessment Application Form Propriety Assessment Form (mandatory for persons not previously assessed on propriety. See also the information on documents to be submitted in the context of fit and proper assessments) Separate declarations of no-objection for each holder of a qualifying holding „ Application form for a declaration of no-objection (DNO) under Section 3:95 of the Wft See our fact sheet on declarations of no-objection under Section 3:95 of the Wft for more information

De Nederlandsche Bank N.V. PO Box 98, 1000 AB Amsterdam +31 (0) 20 524 91 11 dnb.nl/en Follow us on:  Instagram  LinkedIn  X